Mastodon Mastodon Mastodon Mastodon

How Apple Notifies High-Risk Users About Spyware Threats

Photo of author

CyberSecureFox Editorial Team

Published:

Apple has sent a new batch of notifications to users the company suspects are being targeted in attacks involving commercial spyware. According to TechCrunch, the current wave of alerts affects users in 110 countries, and since the notification program launched in late 2021, users in more than 150 countries have received warnings. The notifications are addressed to journalists, activists, politicians, and diplomats — people who are attacked because of their work or status. Apple strongly recommends that recipients of such alerts immediately enable Lockdown Mode and update their devices to the latest version of iOS.

What Apple threat notifications are

According to Apple’s official documentation, the company describes its notifications as alerts issued with a high degree of confidence that a specific user has been targeted by commercial spyware (mercenary spyware). Apple emphasizes that such attacks are characterized by their “extraordinary cost, sophistication, and global scale,” which makes them some of the most advanced digital threats.

The company deliberately does not attribute attacks to specific groups or geographic regions and does not disclose the criteria used to decide when to send notifications. The reason is that any public information about detection methods could help spyware developers adapt their tools.

Notifications are delivered to users through three parallel channels:

  • A notification directly on the device — on the iPhone lock screen and in the “Settings” section
  • An email to the addresses linked to the Apple Account, from [email protected]
  • A banner at the top of the Apple Account page when signing in at account.apple.com

This three-channel delivery is a deliberate safeguard against forgery: a phishing email can imitate an Apple notification, but it is extremely difficult for an attacker to fake a system alert on the device and a banner in the account at the same time. Users who receive a suspicious email should check for the presence of the notification via the other two channels.

Who is at risk

Commercial spyware is not a mass threat. Unlike typical malware that is distributed broadly, these tools are aimed at an extremely limited group of individuals. Developing exploits to deliver the spyware payload requires significant time and financial resources, which makes each attack a bespoke operation.

The main categories of targets are:

  • Journalists working on sensitive investigations
  • Human rights defenders and civil society activists
  • Political figures and government officials
  • Diplomats and staff of international organizations

The scale of the notification program — reportedly more than 150 countries since 2021 — indicates that the commercial spyware industry is not confined to specific regions. It is worth noting that the exact figures for the number of countries are based on secondary sources and are not directly confirmed in Apple’s official documentation.

Practical recommendations

Apple offers a specific set of protective measures that are relevant both for notification recipients and for users in higher-risk groups:

  1. Update iOS to the latest version — each update closes vulnerabilities that may be used to deliver spyware
  2. Enable Lockdown Mode — this mode significantly reduces the attack surface by disabling a number of features that are most often exploited: link previews in messages, incoming FaceTime calls from unknown contacts, and certain web technologies in Safari
  3. Enable two-factor authentication for your Apple Account
  4. Turn on Stolen Device Protection — this feature adds additional biometric checks for critical account operations
  5. Protect your device with a passcode, Touch ID, or Face ID
  6. Install apps only from trusted sources
  7. Do not open links and attachments from unknown senders

For users who have received an Apple threat notification, the highest-priority actions are to immediately enable Lockdown Mode and update iOS. Lockdown Mode is the only measure specifically designed by Apple to counter targeted attacks using commercial spyware, and enabling it should be the first step, not the last item on the checklist. If you fall into one of the potential target categories — journalists, activists, diplomats — turning on this mode is justified as a preventive measure, without waiting for a notification from Apple.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.